WARNING - OLD ARCHIVES

This is an archived copy of the Xen.org mailing list, which we have preserved to ensure that existing links to archives are not broken. The live archive, which contains the latest emails, can be found at http://lists.xen.org/
   
 
 
Xen 
 
Home Products Support Community News
 
   
 

xen-users

[Xen-users] Re: iptables and ipvsadm in domU

To: xen-users@xxxxxxxxxxxxxxxxxxx
Subject: [Xen-users] Re: iptables and ipvsadm in domU
From: Matthew Palmer <mpalmer@xxxxxxxxxxx>
Date: Wed, 2 May 2007 10:31:19 +1000
Delivery-date: Tue, 01 May 2007 17:30:14 -0700
Envelope-to: www-data@xxxxxxxxxxxxxxxxxx
In-reply-to: <4f52331f0705011633i68c6185av288de2cc9f3e9e66@xxxxxxxxxxxxxx>
List-help: <mailto:xen-users-request@lists.xensource.com?subject=help>
List-id: Xen user discussion <xen-users.lists.xensource.com>
List-post: <mailto:xen-users@lists.xensource.com>
List-subscribe: <http://lists.xensource.com/cgi-bin/mailman/listinfo/xen-users>, <mailto:xen-users-request@lists.xensource.com?subject=subscribe>
List-unsubscribe: <http://lists.xensource.com/cgi-bin/mailman/listinfo/xen-users>, <mailto:xen-users-request@lists.xensource.com?subject=unsubscribe>
References: <4f52331f0705011633i68c6185av288de2cc9f3e9e66@xxxxxxxxxxxxxx>
Sender: xen-users-bounces@xxxxxxxxxxxxxxxxxxx
User-agent: Mutt/1.5.11
On Tue, May 01, 2007 at 04:33:02PM -0700, Fong Vang wrote:
> The documentation for Xen mentions that iptables in dom0 may affect
> domUs.  If iptables and ipvsadm is heavily used in a domU, how does this
> impact dom0?

Depends on how your network is setup.

> In my particular case, I want both dom0 and ONE domU (FW_domu) to be visible
> to the external network (eth1).  There will be several other domU's that
> will be behind FW_domU).
> 
> as far as the domUs are concerned, this is the layout.
> 
>       FW_domU
>          |
>       LB_domU
>          |
>    +-----+--+--------+
>    |        |        |
>    domU1    domU2   domU3
> 
> what's the best way to set this up.  LB_domU runs LVS (ipvsadm).  Is this
> configuration even supported in Xen.

It's supported, but complex.  You're going to have to know an awful lot
about bridging, routing, and such to be able to set this up and keep it
running in any sort of good order.  If I were consulting on this, I'd
question the underlying assumptions that have led to this design first, as
there's probably some much simpler way of laying it all out.  But the
diagram above, if given as a virtual network layout, is certainly doable, if
perhaps not optimal.

You can certainly run both iptables and ipvsadm in a Xen domU; it's been an
integral part of one of my clients' setups for about 9 months now, and it
works a treat.

- Matt

-- 
I'm not sure which upsets me more: that people are so unwilling to accept
responsibility for their own actions, or that they are so eager to regulate
everyone else's.

_______________________________________________
Xen-users mailing list
Xen-users@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-users

<Prev in Thread] Current Thread [Next in Thread>